Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 29, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
1311 4.3 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおける不正な認証に関する脆弱性 CWE-863
不正な認証
CVE-2026-12446 2026-06-22 11:42 2026-06-17 Show GitHub Exploit DB Packet Storm
1312 8.8 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおけるヒープベースのバッファオーバーフローの脆弱性 CWE-122
ヒープオーバーフロー
CVE-2026-12447 2026-06-22 11:42 2026-06-17 Show GitHub Exploit DB Packet Storm
1313 8.8 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2026-12448 2026-06-22 11:42 2026-06-17 Show GitHub Exploit DB Packet Storm
1314 7.8 重要
Local
Google Google Chrome GoogleのGoogle Chromeにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-12449 2026-06-22 11:42 2026-06-17 Show GitHub Exploit DB Packet Storm
1315 6.5 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおける権限管理に関する脆弱性 CWE-269
不適切な権限管理
CVE-2026-12450 2026-06-22 11:42 2026-06-17 Show GitHub Exploit DB Packet Storm
1316 8.3 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-12451 2026-06-22 11:42 2026-06-17 Show GitHub Exploit DB Packet Storm
1317 8.8 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-12452 2026-06-22 11:42 2026-06-17 Show GitHub Exploit DB Packet Storm
1318 4.2 警告
Network
Google Google Chrome GoogleのGoogle Chromeにおける入力確認に関する脆弱性 CWE-20
不適切な入力確認
CVE-2026-12453 2026-06-22 11:42 2026-06-17 Show GitHub Exploit DB Packet Storm
1319 8.3 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける競合状態に関する脆弱性 CWE-362
競合状態
CVE-2026-12454 2026-06-22 11:42 2026-06-17 Show GitHub Exploit DB Packet Storm
1320 7.5 重要
Network
Google Google Chrome GoogleのGoogle Chromeにおける解放済みメモリの使用に関する脆弱性 CWE-416
解放済みメモリの使用
CVE-2026-12455 2026-06-22 11:42 2026-06-17 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 29, 2026, 4:19 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
1031 6.5 MEDIUM
Network
kidocode crawl4ai Crawl4AI before 0.8.7 contains an authentication bypass vulnerability in the monitor router endpoints that allows unauthenticated attackers to access destructive operations. Remote attackers can invo… CWE-306
Missing Authentication for Critical Function
CVE-2026-56262 2026-06-26 11:00 2026-06-24 Show GitHub Exploit DB Packet Storm
1032 8.8 HIGH
Network
flowiseai flowise Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an authenticated user can supply a crafted JSON impor… CWE-89
SQL Injection
CVE-2025-71332 2026-06-26 10:59 2026-06-24 Show GitHub Exploit DB Packet Storm
1033 8.8 HIGH
Network
- - Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions. CWE-502
 Deserialization of Untrusted Data
CVE-2026-56053 2026-06-26 09:16 2026-06-25 Show GitHub Exploit DB Packet Storm
1034 7.1 HIGH
Network
- - Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions. CWE-79
Cross-site Scripting
CVE-2026-56014 2026-06-26 09:16 2026-06-25 Show GitHub Exploit DB Packet Storm
1035 8.1 HIGH
Network
- - Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions. CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2026-54845 2026-06-26 09:16 2026-06-25 Show GitHub Exploit DB Packet Storm
1036 9.3 CRITICAL
Network
- - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from n/a through 3.11.5. CWE-89
SQL Injection
CVE-2026-54836 2026-06-26 09:16 2026-06-25 Show GitHub Exploit DB Packet Storm
1037 7.4 HIGH
Network
- - Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. CWE-201
 Insertion of Sensitive Information Into Sent Data
CVE-2026-54821 2026-06-26 09:16 2026-06-25 Show GitHub Exploit DB Packet Storm
1038 9.9 CRITICAL
Network
- - SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, … CWE-79
CWE-1188
Cross-site Scripting
 Insecure Default Initialization of Resource
CVE-2026-54158 2026-06-26 09:16 2026-06-25 Show GitHub Exploit DB Packet Storm
1039 6.1 MEDIUM
Local
- - Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforces workspace roots by check… CWE-22
CWE-59
Path Traversal
Link Following
CVE-2026-53766 2026-06-26 09:16 2026-06-25 Show GitHub Exploit DB Packet Storm
1040 - - - Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS-root>/<oid[0]>/<oid[1]>/<oid>) but per-repo authorization lives in the lfs_obj… CWE-345
CWE-639
CWE-862
 Insufficient Verification of Data Authenticity
 Authorization Bypass Through User-Controlled Key
 Missing Authorization
CVE-2026-52812 2026-06-26 09:16 2026-06-25 Show GitHub Exploit DB Packet Storm